Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Westi on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

pix config errors/ questions: newbie needs help

Status
Not open for further replies.

sonun

IS-IT--Management
Dec 26, 2001
384
US
I am quite new to pix and am playing around to get the hang of it. Now I have installed AD on the same machine as the acs and am trying to get the acs to lookinto AD. I have the cisco doc which I am following to set this up.

I first go into "external user database" -> and set the "windows configuration. Then I go into the "unknown user policy" -> click on "Check the following external user databases" and then select the database under "external database" and then move it into the "selected database" and then click "submit" for which I get a "Number Error 1. The selected DB search list is empty. Correct these errors and submit the form again."
Please advise. What does this mean and what should I do ?

Also, I find this mentioned in the document,
"Performing one of the configuration procedures for an external database that are provided in this chapter
(• By Specific User Assignment
• By Unknown User Policy)
does not on its own instruct Cisco Secure ACS to authenticate any users with that database."
-Can someone kindly explain what they mean and what should I do additionally.

Another thing I am trying to do this. I have different groups setup in AD which has users in those groups. The setup is that the firewall will separate the network into different segments. Each segment will have different resources and hence different security needs. I want to setup ACS such that any user requesting access to a resource in a particular segment will be allowed access to the segment based on group membership. I want to assign different AD groups to each segment. If the user is a member of a group which has been setup to have access to a segment then he should be allowed access. Else s/he shouldnt. Again, I am not sure how to set it up to do that. Any advise on how to do that please.

Another thing mentioned which I thought might be related to what I am trying to do,
"Regardless of whether a user is authenticated by the internal user database or by an external user database, Cisco Secure ACS authorizes network services for users based upon group membership and specific user settings found in the CiscoSecure user database. Thus, all users authenticated by Cisco Secure ACS, even those whose authentication is performed with an external user database, have an account in the CiscoSecure user database."
- What does this mean and what does network services imply here. Does this mean to answer my previous question I would set up network segments as network services and then map those services to groups and the rest will be taken care of. Please advise.

I would appreciate all help, advice, links, tuts, how-tos in this regard.

Thanks bunch
 
Wow, your asking a lot there but I will try in my own strange way to help because your doing what I have done but there are so many circumstances.
You will need to take the info and run.

You said your looking at a doc but I'm not sure which one so I will point you here

Good information there.

Don't overlook this tidbit:
When editing the default group mapping for Windows NT/2000, instead of selecting a valid domain name on the Domain Configurations page, select \DEFAULT.
and make sure you add your domain(s) to the domain list inside of external user database configuration.

MS Groups are added after you get your external user db working. This is done under External user database\Group mappings for:\default.
You have to have the domain in the domain list first or you wont see groups. (This may be where your error lies).


Bottom line though? Wipe what you have done so far on ACS, start from scratch and follow the doc to the T. This way you have know that you didn't miss anything. Plus, you know something you may have done wrong in the past isn't still haunting you.

Check your sec logs on your DC, make sure network settings on the machine are cool, etc. too.


Don't know if that helped one bit but I wish ya luck. This chick here needed lotsa luck figuring out how it was done ;) Hopefully you don't end up spending the same time looking at it as I did.

Good luck and post a follow up on what you did to get it going.

A
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top